Where
-Infinity
0

IBM Db2 Genius Hub29 vulnerabilities

First published (updated )
Advisory
IBM-7279901

Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub

Risk 22
Severity
4.3
First published (updated )

React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

Risk 40
Severity
6.6
First published (updated )

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Risk 38
Severity
6.1
First published (updated )

Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

Risk 37
Severity
6.5
First published (updated )

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Risk 38
Severity
6.1
First published (updated )

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

Risk 38
Severity
6.1
First published (updated )

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Risk 38
Severity
6.1
First published (updated )

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

Risk 68
Severity
10
First published (updated )

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )

Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh

Risk 88
Severity
10
First published (updated )

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

Risk 71
Severity
9.1
First published (updated )

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

Risk 29
Severity
5.3
First published (updated )

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

Risk 71
Severity
9.1
First published (updated )

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

Risk 41
Severity
6.5
First published (updated )

Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

Risk 71
Severity
9.1
First published (updated )

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

Risk 71
Severity
9.1
First published (updated )

Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

Risk 71
Severity
9.1
First published (updated )

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

Risk 85
Severity
8.8
First published (updated )

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

Risk 71
Severity
9.1
First published (updated )

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )

Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix

Risk 33
Severity
6.9
First published (updated )

brace-expansion: Large numeric range defeats documented `max` DoS protection

Risk 43
Severity
7.5
First published (updated )

urllib3: Sensitive headers forwarded across origins in proxied low-level redirects

Risk 41
Severity
8.2
First published (updated )

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Risk 46
Severity
7.5
First published (updated )

RedisBloom RESTORE invalid memory access may allow remote code execution

Risk 83
Severity
7.7
First published (updated )

redis-server RESTORE invalid memory access may allow remote code execution

Risk 84
Severity
7.7
First published (updated )

redis-server Lua use-after-free may allow remote code execution

Risk 84
Severity
6.1
First published (updated )

redis-server use-after-free in unblock client flow may allow remote code execution

Risk 84
Severity
7.7
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203